31 ms·
The DEA Demanded Passwords from LastPass
- milkytron 7y ago> Police were also able to bypass encryption on the suspect’s CyberPowerPC, where they discovered an extension app for LastPass. Mentioning the brand of CyberPowerPC here is irrelevant in my opinion. Last I checked, they only really make cases and do fancy lighting on custom builds which are generally used for gaming and running Windows. It would have been more relevant to say Windows PC, or whatever OS the PC was running. But I suppose it's a bit much to expect Forbes writers to be in tune with this, and the police might not have given more details beyond the brand name.
- zaroth 7y agoMore importantly, how were they able to bypass the encryption?
- Nerevarine76 7y agoThis actually makes me feel even better about LastPass
- goodfight 7y ago/s?
- dmurdoch 7y ago> Even when requests do come in, the company can only provide limited data, they added. That includes customer contact information, billing addresses and IP addresses. It could also reveal what apps a customer is storing passwords for in LastPass > what apps a customer is storing passwords for I guess that means if you have any passwords stored for a website you don't want anyone to know about, put it under a note with an unrelated or gibberish title? The fact they reveal the apps is kinda lame.
- zaroth 7y agoCompetently agree. Why should the app name be available without the master password?
- tinus_hn 7y agoIt might be the user agent sent with the storage and retrieval requests.
- aasasd 7y ago> put it under a note with an unrelated or gibberish title More like, don't use Lastpass if they can't keep all your password-use data on the client side, which is supposed to be their entire shtick? This detail about the metadata leak should be the main outtake, if not the news of the day. When I looked into using Lastpass, I asked them on the support forum why their own documentation says they can alert you when emails you use on websites appear in leaks, if the password database is supposed to be inaccessible by the Lastpass backend. They said I'm reading the docs wrong and it's only the Lastpass account email that they alert about. I re-checked the docs: nope, clearly says website accounts that I put into the database. Here's the thread, which has a screenshot of the docs at that time: https://forums.lastpass.com/viewtopic.php?f=12&t=165485 https://forums.lastpass.com/viewtopic.php?f=12&t=165485 In the end they said the checks are done locally—by downloading dozen-gigabyte leak archives like the exploit.in, I guess? But still I suppose the alert emails are sent server-side. And the support saying I was “misquoting the manual” was enough for me.
- 7y ago